CVE-2022-34888

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/01/2023
Last modified:
08/02/2023

Description

The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:thinkagile_vx3331_firmware:*:*:*:*:*:*:*:* 1.80_afbt20n (excluding)
cpe:2.3:h:lenovo:thinkagile_vx3331:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx_enclosure_certified_node_firmware:*:*:*:*:*:*:*:* 5.20_tei3c8m (excluding)
cpe:2.3:h:lenovo:thinkagile_hx_enclosure_certified_node:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1021_firmware:*:*:*:*:*:*:*:* 3.60_tei386m (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1021:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1320_firmware:*:*:*:*:*:*:*:* 8.40-cdi394n (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1320:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1321_firmware:*:*:*:*:*:*:*:* 8.40-cdi394n (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1321:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1520-r_firmware:*:*:*:*:*:*:*:* 8.40-cdi394n (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1520-r:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx1521-r_firmware:*:*:*:*:*:*:*:* 8.40-cdi394n (excluding)
cpe:2.3:h:lenovo:thinkagile_hx1521-r:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkagile_hx2320-e_firmware:*:*:*:*:*:*:*:* 8.40-cdi394n (excluding)


References to Advisories, Solutions, and Tools